Last updated: September 2026
Twin Hearts ("we", "our", or "us") is a twin pregnancy companion app for expectant parents. This Privacy Policy explains what information we collect, how we use it, your rights under applicable data protection law (including the EU General Data Protection Regulation — GDPR), and how to contact us.
Twin Hearts is operated by Dylan Ndengu, based in the Netherlands. We are the data controller for the personal data described in this policy.
1. Information We Collect
We collect information you provide directly when using the app:
- Account information: your name and email address, used to create and identify your account.
- Pregnancy information: due date, gestational week, twin type (DCDA/MCDA/MCMA), and pregnancy-related preferences.
- Personal details (mama only, optional): date of birth, used to calculate age at due date; whether this is a first pregnancy. These fields are voluntary.
- Country (inferred): we infer your country from your device's locale setting (e.g. "GB" from "en-GB"). No GPS or IP-based location data is collected.
- Health data: maternal weight logs, blood pressure readings, symptom entries, baby kick counts, and scan measurements you choose to enter.
- Wearable data (mama only, optional — off by default): if you turn on Daily Wearable Insights, we read your resting heart rate, sleep duration, and step count from Apple Health or Health Connect. See the "Optional: Daily Wearable Insights" section below.
- Journal entries: notes, memories, and milestones you write within the app.
- Appointment records: upcoming appointments and visit notes you add.
- AI chat messages: messages you send to the Twin Hearts AI assistant, which may include health-related context you choose to share.
- Sonogram images: ultrasound photos you choose to add. These are kept on your device and backed up privately to your account so you don't lose them if you reinstall the app or switch devices, and so your linked partner can see them. Only you and your partner can access them — see "Data Storage and Security".
- Push notification token: a device identifier used to deliver reminders and notifications you enable.
We do not collect any information without your direct input. We do not use advertising trackers, analytics SDKs, or third-party tracking of any kind.
2. Legal Basis for Processing
Under GDPR, we process your personal data on the following legal bases:
- Contract (Article 6(1)(b)): processing your account information, pregnancy data, and app content is necessary to provide the Twin Hearts service you signed up for.
- Explicit consent (Article 9(2)(a)): health and pregnancy data is special category data under GDPR. By ticking the consent checkbox during registration, you explicitly consent to us processing this data to operate the app. Optional features that process special-category data (such as Daily Wearable Insights) have their own separate, unticked opt-in. You may withdraw consent at any time: for an optional feature, switch off its toggle in Settings (this stops the processing and deletes the data collected for it); to withdraw all consent, delete your account.
- Legitimate interests (Article 6(1)(f)): security logging and rate limiting to protect the service and its users.
3. How We Use Your Information
We use the information you provide solely to:
- Operate and personalise the Twin Hearts app experience for you and your partner.
- Sync your pregnancy data between devices linked to the same pregnancy.
- Send you reminders and push notifications you have opted into (supplements, appointments, weekly milestones).
- Power AI-assisted features (the Twin Hearts AI chat and weekly briefings) by sending your messages and relevant pregnancy context to Anthropic's API via our own server. Your messages and pregnancy context (including any health information you share in chat) are transmitted to Anthropic to generate responses. We do not send your name, email address, or raw stored records (weight logs, blood pressure, etc.) to Anthropic unless you include them in a chat message yourself.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Optional: Daily Wearable Insights
Daily Wearable Insights is an optional feature, off by default, available to the mama. It is separate from, and not required for, using Twin Hearts. If you turn it on:
- What we read: once a day we read your resting heart rate, sleep duration, and step count from Apple Health (iOS) or Health Connect (Android), with your device-level permission.
- What we send, and where: we send the last few days of those coded numbers — together with your pregnancy week — to our AI provider, Anthropic (Claude), whose servers are in the United States, to generate a short, supportive wellness note (shown in the app and as an optional push notification). This transfer relies on the EU–US Data Privacy Framework and EU Standard Contractual Clauses. We do not send your name, email, account identifiers, or your symptom entries.
- Sharing with your partner (your choice). There is a "Share with my partner" setting, off by default. If you turn it on, your linked partner can see these insights in the app. Turn it off and only you see them.
- This is not medical advice. The note is a lifestyle wellbeing companion — it offers encouragement, it does not diagnose, monitor, or assess your health, and it is never a substitute for your midwife or doctor. Separate general guidance in the app tells you when to contact your midwife; if anything worries you, contact your midwife or maternity unit.
- Legal basis: your explicit consent (Article 9(2)(a)), given as a separate opt-in.
- Your control and retention: turn it off any time in Settings — we stop reading your wearable and delete the readings we have stored. While it is on, readings are kept for the duration of your pregnancy so you can see your own trend over time, and are automatically deleted after 400 days.
4. Data Storage and Security
Your data is stored securely using Google Firebase, hosted on Google's infrastructure — your pregnancy records in Firestore (a cloud database) and your sonogram images in Firebase Cloud Storage. Access to both is restricted by security rules so that only you and your linked partner can read or write them.
Sonogram images are kept on your device for fast, offline viewing and are also backed up to your private Cloud Storage folder, so they survive reinstalling the app or moving to a new device and so both you and your partner can see them. They are readable only by the members of your pregnancy, and are deleted when you delete the scan or delete your account.
All data in transit is encrypted using TLS. Firebase ID tokens are verified server-side on every AI request; your Anthropic API key is never exposed to the client.
5. Third-Party Sub-Processors
Twin Hearts uses the following third-party services to operate. Each acts as a data processor under a Data Processing Agreement with their respective customers:
- Google Firebase (Firestore, Cloud Storage, Authentication) — data storage, sonogram image storage, and authentication (firebase.google.com/support/privacy)
- Google Sign-In — optional sign-in method (policies.google.com/privacy)
- Expo / EAS — app build and push notification delivery (expo.dev/privacy)
- Anthropic (Claude, United States) — powers the AI chat feature and (if you opt in) Daily Wearable Insights. Processes the chat messages and pregnancy context you send, and — for wearable insights — coded biometric numbers plus your pregnancy week. Transfers rely on the EU–US Data Privacy Framework and EU Standard Contractual Clauses; Anthropic does not use API data to train its models by default. Its primary sub-processor is AWS. (anthropic.com/privacy)
- Namecheap — web hosting for twin-hearts.com (namecheap.com/legal/privacy-policy)
6. Data Retention and Deletion
Your data is retained for as long as your account is active. Wearable readings collected for Daily Wearable Insights are kept for the duration of your pregnancy so you can see your own trend, and are automatically deleted after 400 days; switching the feature off deletes them immediately.
You may delete your account at any time from within the app (Settings → Delete account). When you delete your account, your data enters a 30-day recovery window during which you can restore it. After 30 days, all your personal data is permanently and irreversibly deleted from our systems, including your Firestore records, your sonogram images in Cloud Storage, and your Firebase Auth account.
You may also request deletion by contacting us at hello@twin-hearts.com. We will action deletion requests within 30 days.
7. Children's Privacy
Twin Hearts is intended for use by adults (expectant parents aged 18 and over). We do not knowingly collect information from children under 16. If you believe a child has provided us with personal information, please contact us so we can delete it.
8. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:
- Right of access (Article 15): request a copy of the personal data we hold about you.
- Right to rectification (Article 16): request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): request deletion of your data. You can do this directly in the app or by contacting us.
- Right to restriction (Article 18): request that we restrict processing of your data in certain circumstances.
- Right to data portability (Article 20): request a copy of your data in a structured, machine-readable format to transfer to another service.
- Right to object (Article 21): object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on your consent (including special category health data), you may withdraw it at any time by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to lodge a complaint: you have the right to lodge a complaint with a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
To exercise any of these rights, contact us at hello@twin-hearts.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you within the app. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
- Email: hello@twin-hearts.com
- Website: twin-hearts.com